Form Validation
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing templates, rendered HTML, or shared components related to Validate forms accessibly.
A skill your agent uses when the user explicitly asks to fix and verify a validated or plausible security finding.
$ npx skills add vlinx-io/VelaTerm --skill fix-finding -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vlinx-io/VelaTerm fix-finding --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/fix-finding .claude/skills/fix-finding && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fix-finding" agent skill from https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/fix-finding into .claude/skills/fix-finding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-finding", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/fix-findingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vlinx-io/VelaTerm --skill fix-finding -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vlinx-io/VelaTerm fix-finding --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .agents/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/fix-finding .agents/skills/fix-finding && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fix-finding" agent skill from https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/fix-finding into .agents/skills/fix-finding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-finding", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vlinx-io/VelaTerm --skill fix-finding -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vlinx-io/VelaTerm fix-finding --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/fix-finding .cursor/skills/fix-finding && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fix-finding" agent skill from https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/fix-finding into .cursor/skills/fix-finding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-finding", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vlinx-io/VelaTerm.git --path src-tauri/resources/codex-security/skills/fix-finding--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vlinx-io/VelaTerm --skill fix-finding -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vlinx-io/VelaTerm fix-finding --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/fix-finding .gemini/skills/fix-finding && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fix-finding" agent skill from https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/fix-finding into .gemini/skills/fix-finding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-finding", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vlinx-io/VelaTerm fix-findingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vlinx-io/VelaTerm --skill fix-finding -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .github/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/fix-finding .github/skills/fix-finding && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fix-finding" agent skill from https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/fix-finding into .github/skills/fix-finding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-finding", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vlinx-io/VelaTerm --skill fix-finding -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vlinx-io/VelaTerm fix-finding --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/fix-finding .opencode/skills/fix-finding && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fix-finding" agent skill from https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/fix-finding into .opencode/skills/fix-finding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-finding", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fix-findingA skill your agent uses when the user explicitly asks to fix and verify a validated or plausible security finding.
Fix Finding is an agent skill from vlinx-io/VelaTerm. Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
The repository describes itself as: VelaTerm = Codex + iTerm2, The Best ADE for AI Coding. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 98b5f2f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fix Finding loads about 2.3k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 1,274 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vlinx-io/VelaTerm at commit 98b5f2f, republished under its MIT licence (© vlinx-io). 1,274 words, ~2,321 tokens.
.claude/skills/fix-finding/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Turn a current security finding into a minimal, validated code change. If the code is already safe, prove that and report that no change was needed.
Judge the result in this order:
Never trade an earlier property for a later one. Minimal means the smallest repository-native change that satisfies all earlier properties, not the fewest lines.
Before editing, inspect the affected implementation, its direct callers, nearby helpers, and relevant existing tests. Establish from repository evidence:
Treat the finding as a data-flow and boundary problem, not merely the named input example. Check equivalent encodings, parser forms, aliases, callers, sinks, and every representation or copy of security-sensitive state that could bypass the proposed change. Handle unsafe state explicitly; do not silently accept, truncate, or reinterpret it into another reachable form.
The parent agent owns the patch and independently traces the reported path. Before editing, launch one fresh read-only agent with fork_turns: "none" when delegation is available. If delegation is unavailable, perform the same perspective as a separate pass:
The investigation requires repository-relative evidence and a clear separation between facts, inferences, and unresolved questions. When it completes, reconcile its findings with the parent's investigation and choose the patch boundary.
no_change when repository evidence shows that the reported path is already safe; do not make a speculative change.Return blocked if the vulnerability may be real, but essential evidence, tooling, access, or a product or compatibility decision is missing, so a safe fix cannot be responsibly completed or verified.
After implementing and running focused checks, launch one fresh read-only agent with fork_turns: "none" when delegation is available. Give it only the finding, repository root, authorized scope, repository policy, and current candidate diff; do not provide the patch rationale, investigator report, or claims that tests passed. If delegation is unavailable, perform the same review perspective as a separate pass before final verification. In either case, use the following assignment:
The reviewer must not edit or delegate. Report only concrete, source-backed bypasses or regressions and explain how each can be verified. Treat reviewer findings as hypotheses: confirm them against the source or focused execution before revising the implementation. Address only confirmed issues within the finding and compatibility boundary; do not broaden into speculative concerns or redesign. Then rerun relevant verification and ensure no temporary or unrelated changes remain. Perform only one review cycle.
When a Codex Security workbench request includes a scan ID, occurrence ID, remediation request ID, action token, and expected version, follow only the requested remediation stage. The stage boundary changes when code may be written, but it does not weaken the validation requirements above.
generated or failed using the supplied workbench identity.applied or failed. Do not verify or close the finding in this stage.verified only when the original issue no longer reproduces, legitimate behavior remains intact, and relevant repository checks pass; preserve exact commands and results in the verification summary. Otherwise record failed and state the failing gate or proof gap. Do not close the finding.When a parent thread delegates a remediation stage, the worker owns that stage through its terminal workbench update. The parent remains an orchestrator and must not duplicate the worker's edits or treat a chat response as completion.
In the final response, include:
fixed, no_change, or blockedIf using a scan artifact directory, resolve it using ../../references/scan-artifacts.md, then write a visible report to the fix report path. If there is no existing scan directory, a final chat summary is sufficient unless the user asks for a file.
fixed until every ordered verification gate has passed. Omit a check only when repository evidence shows it is irrelevant; an unavailable relevant check makes verification blocked and must be reported.© vlinx-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in src-tauri/resources/codex-security/skills/fix-finding of vlinx-io/VelaTerm.
Open the folder on GitHubat commit 98b5f2f
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in vlinx-io/VelaTerm, which our catalogue first saw on October 7, 2026.
Fix Finding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fix Finding this skillvlinx-io/VelaTerm | 270 | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Form Validationthedaviddias/Front-End-Checklist | 74k | — | ~633 | Automated safety check: Pass | MIT | |
| No Explicit Anythedaviddias/Front-End-Checklist | 74k | — | ~565 | Automated safety check: Pass | MIT | |
| Runtime Validationthedaviddias/Front-End-Checklist | 74k | — | ~585 | Automated safety check: Pass | MIT | |
| Triage Validationsickn33/agentic-awesome-skills | 47k | 1 repos | ~6.1k | Automated safety check: Pass | MIT | |
| Find Releaseflutter/flutter | 179k | — | ~545 | Automated safety check: Pass | BSD-3-Clause |
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing templates, rendered HTML, or shared components related to Validate forms accessibly.
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing TypeScript files for type safety regressions, during code review of functions that handle external data, or when the codebase has ESLint warnings for…
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing code that calls fetch(), reads from localStorage, accesses process.env, or processes form submissions without explicitly validating the incoming data shape.
sickn33/agentic-awesome-skills
Finding validation before writing any report. An agent skill from sickn33/agentic-awesome-skills.
flutter/flutter
A skill to find the lowest Dart and Flutter release containing a given commit.
agenticnotetaking/arscontexta
Schema validation for notes. An agent skill from agenticnotetaking/arscontexta.
vlinx-io/VelaTerm
Assess an immutable patch artifact's program impact, regression risk, and auto-merge eligibility.
vlinx-io/VelaTerm
Explicitly spawn a standalone child session under the current vlx-term session, passing the task in as its first message (mirrors spawntask).
vlinx-io/VelaTerm
A skill your agent uses when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan.
vlinx-io/VelaTerm
Define, review, or update SECURITY.md guidance for a repository or component.
vlinx-io/VelaTerm
Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories.
vlinx-io/VelaTerm
Use only when the user explicitly requests verification that a security fix remediates a reported vulnerability.
A skill your agent uses when the user explicitly asks to fix and verify a validated or plausible security finding. Fix Finding is an agent skill from vlinx-io/VelaTerm. Use when the user explicitly asks to fix and verify a validated or plausible security finding.
Fix Finding fits situations like: the user explicitly asks to fix and verify a validated; plausible security finding; repository scans.
Run `npx skills add vlinx-io/VelaTerm --skill fix-finding -a claude-code`. Or copy the skill folder (src-tauri/resources/codex-security/skills/fix-finding in vlinx-io/VelaTerm) into .claude/skills/fix-finding in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vlinx-io/VelaTerm --skill fix-finding -a codex`. Or copy the skill folder (src-tauri/resources/codex-security/skills/fix-finding in vlinx-io/VelaTerm) into .agents/skills/fix-finding in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vlinx-io/VelaTerm --skill fix-finding -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-finding, .gemini/skills/fix-finding, .github/skills/fix-finding and .opencode/skills/fix-finding in your project.
SKILL.md names no scripts, command-line tools or credentials: Fix Finding is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fix Finding is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fix Finding: Form Validation (thedaviddias/Front-End-Checklist, 74k stars), No Explicit Any (thedaviddias/Front-End-Checklist, 74k stars), Runtime Validation (thedaviddias/Front-End-Checklist, 74k stars) and Triage Validation (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vlinx-io (a GitHub user) maintains it in vlinx-io/VelaTerm, which has 270 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.
Source: vlinx-io/VelaTerm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.